You must set up the SSG RADIUS proxy feature on the router that has SSG. It enables the SSG to be aware of EAP authentication and process the user's SSG service information sent in the Access-Accept packet. You also must configure the access point (AP) and AZR as the RADIUS proxy client. The AP must use SSG as the authentication, authorization, and accounting (AAA) server for EAP authentication. The AZR must use the Domain Host Configuration Protocol (DHCP) accounting feature and the Address Resolution Protocol (ARP) log feature. SESM must be in RADIUS mode.